← Back to CVE List

CVE-2018-15890

Published: 2019-06-20T17:15Z
Last Modified: 2024-11-21T03:51Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and decoder.readObject in crypto/ECKey.java. When a node syncs and mines a new block, arbitrary OS commands can be run on the server. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt